CVE-2026-59157Medium· 6.5▾ Sunlitwebhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParam…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParamsToShellVars in pkg/api/index.go into the hook script environment without an allowlist. When an upstream reverse proxy did not strip a client-supplied X-WebAuthn-User header and a hook script trusted that variable for identity or privilege, a remote unauthenticated attacker could spoof another user, bypass script security controls, and access or modify resources available to the impersonated identity. This issue is fixed in version 1.22.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/ncarlier/webhookd < 1.22.0Patched in:
github.com/ncarlier/webhookd 1.22.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85751Critical· 9.8Mailu is a mail server distributed as a set of Docker images
CVE-2026-61682Critical· 9.9kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads
CVE-2026-86863Critical· 9.8pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment
CVE-2026-88004High· 7.4Traefik is an open source HTTP reverse proxy and load balancer
CVE-2026-88011High· 8.1Traefik is an open source HTTP reverse proxy and load balancer
CVE-2026-71485Critical· 9.1Centrifugo is an open-source scalable real-time messaging server